Commit graph

2829 commits

Author SHA1 Message Date
4a46a3ba95 Merge remote-tracking branch 'exploitdb/main' 2025-04-04 00:01:15 +00:00
Exploit-DB
c773b14d1c DB: 2025-04-03
6 changes to exploits/shellcodes/ghdb

Mitel mitel-cs018 - Call Data Information Disclosure

SAP NetWeaver - 7.53 - HTTP Request Smuggling

ABB Cylon Aspect 3.08.01 - Remote Code Execution (RCE)

ABB Cylon Aspect 3.08.01 - Arbitrary File Delete

Elaine's Realtime CRM Automation 6.18.17 - Reflected XSS

ProSSHD 1.2 - Denial of Service (DOS)
2025-04-03 00:16:28 +00:00
b737bc0a14 Merge remote-tracking branch 'exploitdb/main' 2025-03-31 00:01:10 +00:00
Exploit-DB
6805102b8a DB: 2025-03-30
3 changes to exploits/shellcodes/ghdb

XWiki Standard 14.10 - Remote Code Execution (RCE)

Solstice Pod 6.2 - API Session Key Extraction via API Endpoint
2025-03-30 00:16:28 +00:00
14e33639d5 Merge remote-tracking branch 'exploitdb/main' 2025-03-30 00:01:12 +00:00
Exploit-DB
353059c64d DB: 2025-03-29
6 changes to exploits/shellcodes/ghdb

Progress Telerik Report Server 2024 Q1 (10.0.24.305) - Authentication Bypass

Sonatype Nexus Repository 3.53.0-01 - Path Traversal

CodeCanyon RISE CRM 3.7.0 - SQL Injection

Litespeed Cache 6.5.0.1 - Authentication Bypass

Rejetto HTTP File Server 2.3m - Remote Code Execution (RCE)
2025-03-29 00:16:38 +00:00
535b1933b6 Merge remote-tracking branch 'exploitdb/main' 2025-03-28 18:47:11 +00:00
01eaff0244 modify get merge and set git config of job 2025-03-28 13:46:20 -05:00
dc6bc24dd7 change url of exploitdb to use their gitlab 2025-03-28 13:43:31 -05:00
189c9f77cf add node container 2025-03-28 13:42:00 -05:00
e3c6b62579 store exploit-db-pull-and-sync.yaml action file 2025-03-28 13:40:21 -05:00
Exploit-DB
15b516383f DB: 2025-03-28
4 changes to exploits/shellcodes/ghdb

KubeSphere 3.4.0 - Insecure Direct Object Reference (IDOR)

MoziloCMS 3.0 - Remote Code Execution (RCE)

X2CRM 8.5 - Stored Cross-Site Scripting (XSS)
2025-03-28 00:16:32 +00:00
Exploit-DB
f33b83aeea DB: 2025-03-27
2 changes to exploits/shellcodes/ghdb

NVIDIA Container Toolkit 1.16.1 - Time-of-check Time-of-Use (TOCTOU)
2025-03-27 00:16:28 +00:00
Exploit-DB
51ef1693d4 DB: 2025-03-23
4 changes to exploits/shellcodes/ghdb

Aztech DSL5005EN Router - 'sysAccess.asp' Admin Password Change (Unauthenticated)

TeamPass 3.0.0.21 - SQL Injection

Microsoft Windows - NTLM Hash Leak Malicious Windows Theme
2025-03-23 00:16:32 +00:00
Exploit-DB
c185b4853b DB: 2025-03-22
2 changes to exploits/shellcodes/ghdb

Jasmin Ransomware - SQL Injection Login Bypass
2025-03-22 00:16:33 +00:00
Exploit-DB
40ceb13974 DB: 2025-03-21
3 changes to exploits/shellcodes/ghdb

FluxBB 1.5.11 - Stored Cross-Site Scripting (XSS)

JUX Real Estate 3.4.0 - SQL Injection
2025-03-21 00:16:35 +00:00
Exploit-DB
04fa5ba95d DB: 2025-03-20
6 changes to exploits/shellcodes/ghdb

Gitea 1.24.0 - HTML Injection

Extensive VC Addons for WPBakery page builder 1.9.0 - Remote Code Execution (RCE)

Loaded Commerce 6.6 - Client-Side Template Injection(CSTI)

TranzAxis 3.2.41.10.26 - Stored Cross-Site Scripting (XSS) (Authenticated)

VeeVPN 1.6.1 - Unquoted Service Path
2025-03-20 00:16:32 +00:00
Exploit-DB
b42ec1de46 DB: 2025-03-19
2 changes to exploits/shellcodes/ghdb

Chamilo LMS 1.11.24 - Remote Code Execution (RCE)
2025-03-19 00:16:27 +00:00
Exploit-DB
731ce583a5 DB: 2024-11-26
3 changes to exploits/shellcodes/ghdb

AEGON LIFE v1.0 Life Insurance Management System - Unauthenticated Remote Code Execution (RCE)
2024-11-26 00:16:28 +00:00
Exploit-DB
773f5f480c DB: 2024-11-16
2 changes to exploits/shellcodes/ghdb

SOPlanning 1.52.01 (Simple Online Planning Tool) - Remote Code Execution (RCE) (Authenticated)
2024-11-16 00:16:32 +00:00
Exploit-DB
b86fb6e1b7 DB: 2024-10-02
4 changes to exploits/shellcodes/ghdb

dizqueTV 1.5.3 - Remote Code Execution (RCE)

reNgine 2.2.0 - Command Injection (Authenticated)

openSIS 9.1 - SQLi (Authenticated)
2024-10-02 00:16:50 +00:00
Exploit-DB
32e0cc5e7f DB: 2024-08-29
5 changes to exploits/shellcodes/ghdb

Gitea 1.22.0 - Stored XSS

NoteMark < 0.13.0 - Stored XSS

Invesalius3 - Remote Code Execution

Windows TCP/IP - RCE Checker and Denial of Service
2024-08-29 00:16:41 +00:00
Exploit-DB
76d99ff06e DB: 2024-08-25
7 changes to exploits/shellcodes/ghdb

Elber ESE DVB-S/S2 Satellite Receiver 1.5.x - Authentication Bypass
Elber ESE DVB-S/S2 Satellite Receiver 1.5.x - Device Config
Elber Wayber Analog/Digital Audio STL 4.00 - Authentication Bypass
Elber Wayber Analog/Digital Audio STL 4.00 - Device Config Disclosure

HughesNet HT2000W Satellite Modem - Password Reset

Aurba 501 - Authenticated RCE
2024-08-25 00:16:25 +00:00
Exploit-DB
809d81619e DB: 2024-08-24
4 changes to exploits/shellcodes/ghdb

Calibre-web 0.6.21 - Stored XSS

Helpdeskz v2.0.2 - Stored XSS
2024-08-24 00:16:35 +00:00
Exploit-DB
507bd26e3e DB: 2024-08-05
6 changes to exploits/shellcodes/ghdb

Ivanti vADC 9.9 - Authentication Bypass

Devika v1 - Path Traversal via 'snapshot_path'

Genexus Protection Server 9.7.2.10 - 'protsrvservice' Unquoted Service Path

Oracle Database 12c Release 1 - Unquoted Service Path

SolarWinds Kiwi Syslog Server 9.6.7.1 - Unquoted Service Path
2024-08-05 00:16:24 +00:00
Exploit-DB
74ee6f57c7 DB: 2024-07-27
2 changes to exploits/shellcodes/ghdb

Monstra CMS 3.0.4 - Remote Code Execution (RCE)
2024-07-27 00:16:34 +00:00
Exploit-DB
c27f5a1741 DB: 2024-07-17
2 changes to exploits/shellcodes/ghdb

Bonjour Service 'mDNSResponder.exe' - Unquoted Service Path Privilege Escalation
2024-07-17 00:16:34 +00:00
Exploit-DB
388e822220 DB: 2024-07-05
1 changes to exploits/shellcodes/ghdb
2024-07-05 00:16:26 +00:00
Exploit-DB
859e322e5c DB: 2024-07-03
13 changes to exploits/shellcodes/ghdb

ASUS ASMB8 iKVM 1.14.51 - Remote Code Execution (RCE) & SSH Access

Zyxel IKE Packet Decoder - Unauthenticated Remote Code Execution (Metasploit)

Rebar3 3.13.2 - Command Injection

Craft CMS Logs Plugin 3.0.3 - Path Traversal (Authenticated)

ZwiiCMS 12.2.04 - Remote Code Execution (Authenticated)

Wipro Holmes Orchestrator 20.4.1 - Log File Disclosure
2024-07-03 00:16:27 +00:00
Exploit-DB
ec14967376 DB: 2024-07-02
5 changes to exploits/shellcodes/ghdb

Azon Dominator Affiliate Marketing Script - SQL Injection

Customer Support System 1.0 - Stored XSS

Microweber 2.0.15 - Stored XSS

Xhibiter NFT Marketplace 1.10.2 - SQL Injection
2024-07-02 00:16:21 +00:00
Exploit-DB
2680e71d44 DB: 2024-06-27
5 changes to exploits/shellcodes/ghdb

SolarWinds Platform 2024.1 SR1 - Race Condition

Automad 2.0.0-alpha.4 - Stored Cross-Site Scripting (XSS)

Flatboard 3.2 - Stored Cross-Site Scripting (XSS) (Authenticated)

Poultry Farm Management System v1.0 - Remote Code Execution (RCE)
2024-06-27 00:16:25 +00:00
Exploit-DB
1064b5c455 DB: 2024-06-15
12 changes to exploits/shellcodes/ghdb

Zyxel IKE Packet Decoder - Unauthenticated Remote Code Execution (Metasploit)

Rebar3 3.13.2 - Command Injection
AEGON LIFE v1.0 Life Insurance Management System - SQL injection vulnerability.
AEGON LIFE v1.0 Life Insurance Management System - Stored cross-site scripting (XSS)
AEGON LIFE v1.0 Life Insurance Management System - Unauthenticated Remote Code Execution (RCE)

Boelter Blue System Management 1.3 - SQL Injection

Carbon Forum 5.9.0 - Stored XSS

PHP < 8.3.8 - Remote Code Execution (Unauthenticated) (Windows)

WP-UserOnline 2.88.0 - Stored Cross Site Scripting (XSS) (Authenticated)

XMB 1.9.12.06 - Stored XSS

ZwiiCMS 12.2.04 - Remote Code Execution (Authenticated)
2024-06-15 00:16:21 +00:00
Exploit-DB
a99f08beda DB: 2024-06-08
2 changes to exploits/shellcodes/ghdb

Backdrop CMS 1.27.1 - Remote Command Execution (RCE)
Backdrop CMS 1.27.1 - Authenticated Remote Command Execution (RCE)
2024-06-08 00:16:25 +00:00
Exploit-DB
8a32e340d5 DB: 2024-06-04
8 changes to exploits/shellcodes/ghdb

Sitefinity 15.0 - Cross-Site Scripting (XSS)

appRain CMF 4.0.5 - Remote Code Execution (RCE) (Authenticated)

CMSimple 5.15 - Remote Code Execution (RCE) (Authenticated)

Dotclear 2.29 - Remote Code Execution (RCE)

Monstra CMS 3.0.4 - Remote Code Execution (RCE)

Serendipity 2.5.0 - Remote Code Execution (RCE)

WBCE CMS v1.6.2 - Remote Code Execution (RCE)
2024-06-04 00:16:25 +00:00
Exploit-DB
ea4df5672e DB: 2024-06-02
6 changes to exploits/shellcodes/ghdb

ASUS ASMB8 iKVM 1.14.51 - Remote Code Execution (RCE) & SSH Access

Akaunting 3.1.8 - Server-Side Template Injection (SSTI)

Craft CMS Logs Plugin 3.0.3 - Path Traversal (Authenticated)

FreePBX 16 -  Remote Code Execution (RCE) (Authenticated)

Wipro Holmes Orchestrator 20.4.1 - Log File Disclosure
2024-06-02 00:16:32 +00:00
Exploit-DB
3ac07794c9 DB: 2024-06-01
7 changes to exploits/shellcodes/ghdb

Aquatronica Control System 5.1.6 - Information Disclosure

Check Point Security Gateway - Information Disclosure (Unauthenticated)

changedetection < 0.45.20 - Remote Code Execution (RCE)

BWL Advanced FAQ Manager 2.0.3 - Authenticated SQL Injection

ElkArte Forum 1.1.9 - Remote Code Execution (RCE) (Authenticated)

iMLog < 1.307 - Persistent Cross Site Scripting (XSS)
2024-06-01 00:16:48 +00:00
Exploit-DB
094f6f9304 DB: 2024-05-20
7 changes to exploits/shellcodes/ghdb

Apache OFBiz 18.12.12 - Directory Traversal

Backdrop CMS 1.27.1 - Remote Command Execution (RCE)

htmlLawed 1.2.5 - Remote Code Execution (RCE)

PopojiCMS 2.0.1 - Remote Command Execution (RCE)

Rocket LMS 1.9 - Persistent Cross Site Scripting (XSS)

Wordpress Theme XStore 9.3.8 - SQLi
2024-05-20 00:16:24 +00:00
Exploit-DB
323c36e831 DB: 2024-05-16
2 changes to exploits/shellcodes/ghdb

Gibbon LMS < v26.0.00 - Authenticated RCE
2024-05-16 00:16:39 +00:00
Exploit-DB
9d17a3d6ca DB: 2024-05-14
10 changes to exploits/shellcodes/ghdb

CrushFTP < 11.1.0 - Directory Traversal

Apache mod_proxy_cluster - Stored XSS

CE Phoenix Version 1.0.8.20 - Stored XSS

Chyrp 2.5.2 - Stored Cross-Site Scripting (XSS)

Leafpub 1.1.9 - Stored Cross-Site Scripting (XSS)

Prison Management System - SQL Injection Authentication Bypass

PyroCMS v3.0.1 - Stored XSS

Plantronics Hub 3.25.1 - Arbitrary File Read
2024-05-14 00:16:26 +00:00
Exploit-DB
edacab1df2 DB: 2024-05-09
3 changes to exploits/shellcodes/ghdb

iboss Secure Web Gateway - Stored Cross-Site Scripting (XSS)

Clinic Queuing System 1.0 - RCE
2024-05-09 00:16:23 +00:00
Exploit-DB
b8a68091fe DB: 2024-05-05
7 changes to exploits/shellcodes/ghdb

Elber Cleber/3 Broadcast Multi-Purpose Platform 1.0.0 - Authentication Bypass
Elber Reble610 M/ODU XPIC IP-ASI-SDH Microwave Link - Authentication Bypass
Elber Reble610 M/ODU XPIC IP-ASI-SDH Microwave Link - Device Config Disclosure
Elber Signum DVB-S/S2 IRD For Radio Networks 1.999 - Authentication Bypass
Elber Signum DVB-S/S2 IRD For Radio Networks 1.999 - Device Config Disclosure

Elber Cleber/3 Broadcast Multi-Purpose Platform 1.0.0 - Device Config Disclosure
2024-05-05 00:16:37 +00:00
Exploit-DB
67e4434322 DB: 2024-05-02
1 changes to exploits/shellcodes/ghdb
2024-05-02 00:16:56 +00:00
Exploit-DB
9eb5c7b425 DB: 2024-04-22
7 changes to exploits/shellcodes/ghdb

Palo Alto PAN-OS  < v11.1.2-h3  - Command Injection and Arbitrary File Creation

FlatPress v1.3 - Remote Command Execution

Laravel Framework 11 - Credential Leakage

SofaWiki 3.9.2 - Remote Command Execution (RCE) (Authenticated)

Wordpress Plugin Background Image Cropper v1.2 - Remote Code Execution

Flowise 1.6.5 - Authentication Bypass
2024-04-22 00:16:25 +00:00
Exploit-DB
4ab159b6a8 DB: 2024-04-20
1 changes to exploits/shellcodes/ghdb
2024-04-20 00:16:33 +00:00
Exploit-DB
27ecd9e84b DB: 2024-04-16
5 changes to exploits/shellcodes/ghdb

Jenkins 2.441 - Local File Inclusion
OpenClinic GA 5.247.01 - Information Disclosure
OpenClinic GA 5.247.01 - Path Traversal (Authenticated)

djangorestframework-simplejwt 5.3.1 - Information Disclosure
2024-04-16 00:16:46 +00:00
Exploit-DB
b59144d74e DB: 2024-04-14
6 changes to exploits/shellcodes/ghdb

BMC Compuware iStrobe Web - 20.13 - Pre-auth RCE

Online Fire Reporting System OFRS  - SQL Injection Authentication Bypass

Savsoft Quiz v6.0 Enterprise - Stored XSS

Stock Management System v1.0 - Unauthenticated SQL Injection
2024-04-14 00:16:33 +00:00
Exploit-DB
aa67db6cea DB: 2024-04-13
15 changes to exploits/shellcodes/ghdb

MinIO < 2024-01-31T20-20-33Z - Privilege Escalation

PrusaSlicer 2.6.1 - Arbitrary code execution

GUnet OpenEclass E-learning platform 3.15 - 'certbadge.php' Unrestricted File Upload

HTMLy Version v2.9.6 - Stored XSS

Moodle 3.10.1 - Authenticated Blind Time-Based SQL Injection - _sort_ parameter

PopojiCMS Version 2.0.1 - Remote Command Execution

Quick CMS v6.7 en 2023 - 'password' SQLi

Service Provider Management System v1.0 - SQL Injection

WBCE 1.6.0 - Unauthenticated SQL injection

WBCE CMS Version 1.6.1 - Remote Command Execution (Authenticated)

Wordpress Plugin Playlist for Youtube 1.32 - Stored Cross-Site Scripting (XSS)

Wordpress Plugin WP Video Playlist 1.1.1 - Stored Cross-Site Scripting (XSS)

Ray OS v2.6.3 - Command Injection RCE(Unauthorized)

Terratec dmx_6fire USB - Unquoted Service Path
2024-04-13 00:16:27 +00:00
Exploit-DB
034fafa3fd DB: 2024-04-09
8 changes to exploits/shellcodes/ghdb

Positron Broadcast Signal Processor TRA7005 v1.20 - Authentication Bypass

Best Student Result Management System v1.0 - Multiple SQLi

Daily Expense Manager 1.0 - 'term' SQLi

Human Resource Management System v1.0 - Multiple SQLi

Open Source Medicine Ordering System v1.0 - SQLi

Wordpress Theme Travelscape v1.0.3 - Arbitrary File Upload

AnyDesk 7.0.15 - Unquoted Service Path
2024-04-09 00:16:23 +00:00
Exploit-DB
a06b0db78d DB: 2024-04-04
6 changes to exploits/shellcodes/ghdb

Computer Laboratory Management System v1.0 - Multiple-SQLi

Petrol Pump Management Software v1.0 - Remote Code Execution (RCE)

Quick CMS v6.7 en 2023 - 'password' SQLi

Wordpress Plugin Alemha Watermarker 1.3.1 - Stored Cross-Site Scripting (XSS)

ESET NOD32 Antivirus 17.0.16.0 - Unquoted Service Path
2024-04-04 00:16:33 +00:00
Exploit-DB
a44e138f78 DB: 2024-04-03
28 changes to exploits/shellcodes/ghdb

Casdoor < v1.331.0 - '/api/set-password' CSRF

GL-iNet MT6000 4.5.5 - Arbitrary File Download

Axigen < 10.5.7 - Persistent Cross-Site Scripting

Blood Bank v1.0 - Stored Cross Site Scripting (XSS)

CE Phoenix v1.0.8.20 - Remote Code Execution
Daily Habit Tracker 1.0 - Broken Access Control
Daily Habit Tracker 1.0 - SQL Injection
Daily Habit Tracker 1.0 - Stored Cross-Site Scripting (XSS)

E-INSUARANCE v1.0 - Stored Cross Site Scripting (XSS)

Elementor Website Builder < 3.12.2 - Admin+ SQLi
Employee Management System 1.0 - _txtfullname_ and _txtphone_ SQL Injection
Employee Management System 1.0 - _txtusername_ and _txtpassword_ SQL Injection (Admin Login)
FoF Pretty Mail 1.1.2 - Local File Inclusion (LFI)
FoF Pretty Mail 1.1.2 - Server Side Template Injection (SSTI)

Gibbon LMS v26.0.00 - SSTI vulnerability

Hospital Management System v1.0 - Stored Cross Site Scripting (XSS)

LeptonCMS 7.0.0 - Remote Code Execution (RCE) (Authenticated)

Online Hotel Booking In PHP 1.0 - Blind SQL Injection (Unauthenticated)

OpenCart Core 4.0.2.3 - 'search' SQLi

Petrol Pump Management Software v1.0 - Remote Code Execution (RCE)

Simple Backup Plugin Python Exploit 2.7.10 - Path Traversal

Smart School 6.4.1 - SQL Injection

Wordpress Plugin - Membership For WooCommerce < v2.1.7 - Arbitrary File Upload to Shell (Unauthenticated)

ASUS Control Center Express 01.06.15 - Unquoted Service Path

Microsoft Windows 10.0.17763.5458 - Kernel Privilege Escalation

Microsoft Windows Defender - Detection Mitigation Bypass TrojanWin32Powessere.G

Rapid7 nexpose - 'nexposeconsole' Unquoted Service Path
2024-04-03 00:16:27 +00:00